Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I guess the actual shell code starts from line 40 ">>stream..."

It must be using some other encoding, only if we knew which!



It's a PDF FlateDecode block, i.e. it's DEFLATEd. The actual payload within may be different, but this much has been used before.

http://digdog.tumblr.com/post/894317027/jailbreak-with-pdf-f...


It's presumably just a lump of binary ARM opcodes.


We need a debugger or a disassmbler like IDA Pro to make reverse engineering of that code




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: